Manage security assessments for various vendor types, including Professional Services, SaaS, SaaS+Professional, and On-Premises. Communicate security requirements and risk profiles across the organization, educating stakeholders on securely integrating third-party vendors. Collaborate with security leaders, engineers, and cross-functional teams to safeguard company assets and ensure regulatory compliance and protect New Relic employees and customers from security and privacy threats. Support and manage projects and tasks part of the third-party risk and security assessment lifecycle. Attention to detail, the ability to handle changing priorities, and a passion for process automation and education are critical for success in this role.
Key Responsibilities
Vendor Security Assessments:
Support the lifecycle of third-party tooling within the enterprise across all business units, including initial security review, ongoing annual reviews and ad-hoc reviews due to use case changes.
Security reviews include vendors with access to data and systems supporting New Relic Product.
Review vendor-provided security artifacts for alignment with strong security practices and regulatory compliance (ISO 27001, SOC 2, PCI-DSS etc..)
Assess AI-driven tools and SaaS platforms, identifying security risks and implementing secure recommendations.
Keep abreast of the latest cybersecurity trends, emerging threats and evolving standards in third- party risk management, ensuring that New Relics security practices remain ahead of the curve.
Ongoing Monitoring and Risk Remediation:
Continuously monitor vendor risks, maintain risk profiles, and develop remediation plans for identified issues.
Automate vendor inventory tracking and streamline workflows for managing approved and unapproved tools.
Process Development and Integration:
Manage risk assessment frameworks tailored to vendor types and business needs.
Execute auditing processes, including SSO implementation reviews and SaaS access controls.
Drive technical solutions to manage vendor inventory and improve operational efficiency.
Metrics and Reporting:
Define KPIs and develop dashboards to track vendor risk management performance.
Communicate risk insights, metrics, and remediation progress to leadership.
Collaboration and Education:
Collaborate with cross-functional teams for vendor security events, complete client questionnaires, and assist with customer security escalations.
Work with cross-functional teams to align technical risks with business goals.
Educate internal teams on securely adopting and managing external vendors.
Support the Enterprise business with project and reporting generated by Third-party management tools.
Stay informed on cybersecurity trends, compliance requirements, and best practices.
This role requires
Minimum 5 years of experience in third-party risk management, vendor security assessments.
Proven expertise in evaluating diverse vendor types and implementing risk mitigation strategies.
Understanding of data privacy principles and third-party handling of various classes of enterprise and customer data.
Experience assessing vendors using LLM or AI capabilities.
Ability to learn about new tools and technology, their security configurations, and identify areas of risk.
Strong knowledge of SaaS security, SSO configurations, and AI tool evaluations.
Demonstrated success in process automation, workflow optimization, and scaling security operations.
Exceptional communication skills and the ability to present metrics to senior leadership.
Bonus points if you have
Experience with Salesforce, GRC tools, and SaaS inventory management.
Familiarity with security frameworks like ISO 27001, SOC 2, and NIST.
Understanding of policy development and risk management for technical integrations.